🔴 Getting Started with the Portable Executable File Format

Dr Josh Stroschein - The Cyber Yeti
Dr Josh Stroschein - The Cyber Yeti
7.6 هزار بار بازدید - 2 سال پیش - Understanding file formats is essential
Understanding file formats is essential to being able to analyze them effectively. Microsoft's portable executable, commonly referred to as PE, is one of the most important out there, as it contains executable code for the Windows operating system. In this session, we'll take a look at the basics of this binary file format by first creating sample programs, then analyzing them using a hex editor. We'll identify common characteristics of PE files, those often used in signatures, as well as begin to explore internal data structures. We'll also begin to explore the differences of these files when they reside on disk and when they are loaded into memory for execution. So dust off that hex-editor and join me as we start to scratch the surface of the PE file format!
2 سال پیش در تاریخ 1401/04/09 منتشر شده است.
7,635 بـار بازدید شده
... بیشتر